Legal

Cookie Notice

Version 1.0
Effective date: August 21, 2026
Last updated: August 21, 2026

This notice is part of the Cutvey Privacy Policy. It explains the cookies and similar technologies Cutvey LLC uses, by category and purpose, across our web app, our marketing and product websites, our native apps and our email.

We have kept this short because there is very little to report. Cutvey runs no advertising cookies, no third-party analytics cookies and no cross-site tracking, anywhere. That is a product decision, not a temporary state.

1. The web app (including custom domains and the client and crew portals)

Strictly necessary cookies only. Without them the app cannot sign you in or keep you safe.

Cookie Purpose Type Lifetime
Session cookieKeeps you signed in to your workspace. Signed, HTTP-only, and revocable from SettingsStrictly necessary, first partyUntil you sign out, or the session expires
Sign-in and device cookieRemembers a device you marked as trusted, so you are not asked for a code every timeStrictly necessary, first partyUntil you revoke the device
Security and anti-abuse cookieCross-site request forgery protection and rate limitingStrictly necessary, first partySession, or short-lived
Preference storageRemembers a choice you made in the app, such as the theme you picked or the view you last used. Kept in your browser's local storage, not sent to our servers. We store it only because you chose it, and storing it is the only way to give you what you asked forStrictly necessary, first partyUntil you clear your browser data

These are strictly necessary to deliver the service you asked for. Under the EU ePrivacy rules and the UK Privacy and Electronic Communications Regulations they do not require consent, which is why you do not see a cookie consent banner in the app today.

We class nothing as strictly necessary that we would not defend as strictly necessary. Everything above is either what signs you in, what keeps the app safe, or what remembers a choice you actively made. If we ever store or read anything on your device for another reason, including measurement, we will ask you first and give you a way to change your answer.

2. The marketing and product websites

Our public websites set no analytics cookies, no advertising cookies and no third-party tracking of any kind. We do not use Google Analytics, Meta pixels, LinkedIn Insight, TikTok pixels or anything comparable.

The only cookies you may meet come from the infrastructure that keeps the sites up and keeps bots off our forms:

Cookie Set by Purpose Lifetime
Bot-protection tokenCloudflare, Inc. (Turnstile), on our behalfConfirms that a human, not a bot, is submitting a contact, support or lead form. Cloudflare states that Turnstile does not use this data for advertising and does not track users across sites. We do not receive an advertising profile or a cross-site identifier from it, and we would not use oneMinutes, tied to the form submission
Infrastructure cookie (for example __cf_bm)Cloudflare, Inc.Tells human traffic from automated traffic so the site stays available. Strictly necessary for securityUp to 30 minutes

Lead forms in a studio's client portal. A studio's own lead-capture form, served through Cutvey, is protected the same way, using that studio's own configured keys. The studio is the controller of what the form collects.

3. The native apps

This section applies to every Cutvey native application, current and future. The Privacy Policy's product table lists them.

Native apps do not use cookies. They store what they need on your device and, where you turn it on, in your own iCloud. In practice what an app keeps on the device is: your settings, your own content, a sign-in token if you signed in, a record of the analytics answer you gave, and a cache of what you last worked on. None of it is shared with anyone else, and deleting the app removes it from the device. Apps contain no advertising SDKs, no attribution SDKs and no cross-site or cross-app tracking technology. Where an app includes a component from a service provider to send us crash reports, that provider is on our subprocessor list and may use the reports only to provide that service to us.

Usage data and crash reports in the apps follow section 8 of the Privacy Policy. Optional usage data and crash reports are on by default where the law allows a default. In the European Economic Area, the United Kingdom, Switzerland, and anywhere else whose law requires your agreement before an app reads or stores this kind of information on your device, every app asks you on first run and collects nothing until you agree. Wherever you are, you can change the answer at any time in the App's Settings. Because there is no advertising or attribution technology in any app, you do not see an App Tracking Transparency prompt. The permission we ask for is about improving our own software, not about following you anywhere else.

4. Email

Our own email to you. Sign-in codes, receipts, invoices, notifications and security alerts record only delivery and bounce events, because we need to know the message arrived. They carry no tracking pixel.

Our product announcements do record opens and link clicks, so we can tell whether an announcement was worth sending. Measuring an open means loading a small image from our servers, which counts as access to your device under European and UK rules. So we ask for your agreement to that measurement when you subscribe, if you are in the European Economic Area, the United Kingdom or Switzerland. We do not measure opens for anyone who has not agreed. To withdraw, use the preference link in any announcement, or email [email protected]. We record your answer against your email address and apply it to every later message. Every announcement also carries a one-click unsubscribe.

Email a studio sends through Cutvey. A proposal, invoice, call sheet or gallery link that a studio sends to its own client can carry a small tracking image and click-tracked links, so the studio can tell whether the client opened it. The studio decides whether to use tracking and on whom. Our Terms require the studio to disclose it to recipients where its law requires, and to honor a recipient who asks to be emailed without tracking. We build and host the measurement, we secure the data, and we provide the off switch. Every workspace can turn tracking off for all of its outgoing mail in Settings. The engagement data stays in the studio's workspace and we never use it for our own marketing.

If you received such an email and do not want the open counted, most email clients can block remote images, which stops the image from loading. Blocking images does not affect link clicks: if you click a link in the message, the sender can still see that you did. To stop it entirely, ask the studio that sent it.

5. Controlling cookies

You can delete or block cookies in your browser settings. Blocking the strictly necessary cookies in section 1 stops you from signing in to the app, which is the whole of what they do.

Because we set nothing beyond strictly necessary on the web, there is no consent preference for you to manage there and no "reject non-essential cookies" button to press. Our native apps are different: where the law requires it they ask you on first run about usage data and crash reporting, because that involves reading information from your device, and wherever you are you control the answer in the App's Settings. If the web app ever needs the same question asked, we will ask it there too.

6. Changes and contact

We update this notice whenever the technologies we use change, and the "Last updated" date above tells you when. Material changes are notified as described in section 20 of the Privacy Policy. When this notice changes, the version it replaces will be kept at https://cutvey.com/legal/archive.

Questions: [email protected].